Логотип exploitDog
bind:CVE-2020-20640
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-20640

Количество 2

Количество 2

nvd логотип

CVE-2020-20640

больше 4 лет назад

Cross Site Scripting (XSS) vulnerability in ECShop 4.0 due to security filtering issues, in the user.php file, we can use the html entity encoding to bypass the security policy of the safety.php file, triggering the xss vulnerability.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-v739-645c-vfcr

больше 3 лет назад

Cross Site Scripting (XSS) vulnerability in ECShop 4.0 due to security filtering issues, in the user.php file, we can use the html entity encoding to bypass the security policy of the safety.php file, triggering the xss vulnerability.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-20640

Cross Site Scripting (XSS) vulnerability in ECShop 4.0 due to security filtering issues, in the user.php file, we can use the html entity encoding to bypass the security policy of the safety.php file, triggering the xss vulnerability.

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-v739-645c-vfcr

Cross Site Scripting (XSS) vulnerability in ECShop 4.0 due to security filtering issues, in the user.php file, we can use the html entity encoding to bypass the security policy of the safety.php file, triggering the xss vulnerability.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу